All certifications / CKAD / Lessons
CKAD CKAD (Kubernetes v1.35 curriculum) lessons
Study CKAD for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CKAD study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Application Design and Build
- Writing Dockerfiles: base images, layers, multi-stage builds, ENTRYPOINT vs CMD
- Building, tagging, saving and loading images with docker or podman (build, tag, save, load)
- How Pod `command` and `args` override the image ENTRYPOINT and CMD
- Choosing a workload: Deployment, StatefulSet, DaemonSet, Job, CronJob, bare Pod
- Jobs: completions, parallelism, backoffLimit, activeDeadlineSeconds, restartPolicy Never/OnFailure
- CronJobs: schedule syntax, concurrencyPolicy, history limits, running a job manually from a CronJob
- Multi-container patterns: init containers, sidecars (including native sidecars with restartPolicy: Always), adapter and ambassador
- Ephemeral volumes: emptyDir (including medium: Memory), configMap/secret/projected volumes
- Persistent storage: PersistentVolume, PersistentVolumeClaim, StorageClass, access modes, dynamic provisioning
- Mounting volumes with volumeMounts, mountPath, subPath and readOnly
Domain 2: Application Deployment
- Deployments and ReplicaSets: how the Pod template, labels and selectors fit together
- Rolling updates: maxSurge, maxUnavailable, minReadySeconds; the Recreate strategy
- Kubectl rollout status, history, undo (--to-revision), pause and resume; kubectl set image and scale
- Blue/green deployments by switching a Service selector between two Deployments
- Canary releases with two Deployments behind one Service, weighted by replica count
- Helm basics: repositories, charts, releases; helm repo add/update, search, install, upgrade, rollback, uninstall, list
- Helm values: helm show values, --set and -f values.yaml, helm template, namespaces with -n and --create-namespace
- Kustomize: kustomization.yaml, resources, namePrefix, namespace, commonLabels/labels, images, patches, configMapGenerator
- Applying overlays with kubectl apply -k and previewing with kubectl kustomize
Domain 3: Application Observability and Maintenance
- API deprecations and removals: finding current apiVersions with kubectl api-resources, api-versions and explain
- Updating manifests to supported API groups (networking.k8s.io/v1 Ingress, batch/v1 CronJob, autoscaling/v2 HPA)
- Liveness, readiness and startup probes; httpGet, tcpSocket, exec and grpc handlers; timing fields
- What each probe failure does: restart the container vs remove the Pod from Service endpoints
- Kubectl get, describe, get events, top pod/node (metrics-server) for monitoring
- Container logs: kubectl logs with -c, -f, --previous, --tail, --since, -l and deploy/<name>
- Reading Pod status: Pending, ImagePullBackOff, CrashLoopBackOff, OOMKilled, Completed, exit codes
- Debugging: kubectl exec, kubectl debug (ephemeral containers and Pod copies), port-forward, temporary busybox Pods
- Output tricks for fast troubleshooting: -o wide, -o yaml, jsonpath, --show-labels, --sort-by
Domain 4: Application Environment, Configuration and Security
- Extending Kubernetes: CustomResourceDefinitions, custom resources and Operators; discovering them with kubectl get crd and api-resources
- Request flow: authentication, authorization (RBAC) and admission control (mutating and validating)
- RBAC objects: Role, ClusterRole, RoleBinding, ClusterRoleBinding; kubectl auth can-i with --as
- Resource requests and limits for CPU and memory; units (m, Mi, Gi); QoS classes
- Namespace ResourceQuota and LimitRange defaults
- ConfigMaps: create from literals, files and env files; consume as env, envFrom and volumes
- Secrets: generic, docker-registry and tls types; base64 encoding vs encryption; secretKeyRef and volume mounts
- ServiceAccounts: serviceAccountName, token projection, automountServiceAccountToken, kubectl create token
- SecurityContext at Pod and container level: runAsUser, runAsNonRoot, fsGroup, readOnlyRootFilesystem, allowPrivilegeEscalation
- Linux capabilities (add/drop) and Pod Security Admission levels (privileged, baseline, restricted)
Domain 5: Services and Networking
- Service types: ClusterIP, NodePort, LoadBalancer, ExternalName and headless (clusterIP: None)
- Selectors, port vs targetPort vs nodePort, named ports
- EndpointSlices and why an empty endpoint list means the selector or readiness is wrong
- Cluster DNS names: <service>.<namespace>.svc.cluster.local
- Kubectl expose, kubectl create service and kubectl port-forward
- NetworkPolicy basics: podSelector, policyTypes, ingress and egress rules, default deny
- NetworkPolicy peers: podSelector, namespaceSelector, ipBlock; AND vs OR rule semantics; allowing DNS on egress
- NetworkPolicy needs a CNI plugin that enforces it (for example Calico or Cilium)
- Ingress resources: ingressClassName, host and path rules, pathType Prefix vs Exact, default backend, TLS secrets
- Ingress controllers (for example ingress-nginx) and testing with curl and Host headers